CVE Vulnerabilities

CVE-2014-5403

Use of Hard-coded Cryptographic Key

Published: Apr 03, 2015 | Modified: Nov 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Hospira MedNet before 6.1 uses hardcoded cryptographic keys for protection of data transmission from infusion pumps, which allows remote attackers to obtain sensitive information by sniffing the network.

Weakness

The product uses a hard-coded, unchangeable cryptographic key.

Affected Software

Name Vendor Start Version End Version
Mednet Hospira * 5.8 (including)

Potential Mitigations

References